Many businesses dealing in cybersecurity products may, in certain situations, be confused by the practical question: Is this device subject to a business license requirement or not? Does the product contain civil cryptography elements? And in practice, not a few shipments of servers, routing devices or storage hardware have been held up at customs simply because technical documents contain encryption algorithms (such as AES, RSA, IPsec), leaving businesses confused as to whether the products fall under the regulatory authority of the Government Cipher Committee, the Ministry of Public Security or are completely exempt. Conversely, many businesses have spent months carrying out licensing procedures for devices that are inherently intended only for common IT needs.
Officially effective from September 1, 2026, Decree No. 341/2026/ND-CP establishes a clear technical framework: Setting a firm boundary for 07 groups of specialized civil cryptography products that are required to obtain a license, officially relieving the administrative burden for 12 groups of common IT products, while also establishing a legal framework for dual-use products that contain both cybersecurity and civil cryptography elements in the same product.

1. Core Concepts & General Business Conditions
Definition of Civil Cryptography Products (CCP): Hardware, software, technical equipment, or professional documents using cryptographic techniques (symmetric or asymmetric algorithms) to protect information that does not constitute state secrets (Article 3.1).
Mandatory Licensing Requirements:
Business Conditions: Enterprises conducting business in civil cryptography products and services within the scope of regulation must satisfy the prescribed conditions and obtain a Business License from the Government Cipher Committee. The license is valid for up to 10 years as prescribed.
Product Requirements: Products falling within the scope of regulation must meet requirements on quality, standards, technical regulations, and conformity declaration/certification as prescribed before being placed on the market and put into circulation.
2. 07 groups of civil cryptography products subject to specialized regulatory management (Appendix I)
Appendix I identifies groups of products, devices and software using cryptographic techniques that fall within the scope of regulation, under which enterprises conducting business must satisfy the applicable conditions and carry out licensing procedures as prescribed:
- Group 1: Products for cryptographic key generation, management or storage: HSM hardware modules, PKI USB Tokens, PKI Smartcards, SIM PKI.
- Group 2: Products for securing stored data: Devices, smart cards, USBs, memory chips or cloud solutions for encrypting/decrypting data at rest.
- Group 3: Products for securing data exchanged over networks: Devices/software for encrypting and digitally signing data transmitted over communication channels (excluding IP flow products).
- Group 4: Products for securing IP flows: Devices and software for creating secure virtual private networks such as IPsec VPN, TLS VPN, MACsec.
- Group 5: Products for securing analog voice and digital voice: Devices/software for encrypting audio and video over ZRTP, SRTP, WebRTC, SIPS protocols.
- Group 6: Products for securing wireless communications: Wireless transmission/transceiver devices using encryption algorithms.
- Group 7: Products for securing fax and telegraph communications: Printers/copiers/fax machines with integrated data encryption for stored data or data in transit.
3. 12 groups of IT products excluded from licensing (annex I)
Appendix I specifically identifies 12 groups of IT products that use cryptography techniques but are excluded from the scope of conditional civil cryptographic products and services. This delimitation helps enterprises determine the right licensing obligations on the basis of the functions, purposes and technical characteristics of the product.
Group of common commercial equipment and software:
- Operating systems, browsers, software with sub-cipher features available, users install them themselves.
- Mass Consumer Electronics: Tablets, digital cameras, cameras, DVD players.
- Mobile phones without end-to-end encryption.
Network Infrastructure, Governance and Cyber Security Group:
- The product only has an authentication function, no data encryption function.
- The product uses cryptography technology only for the purpose of monitoring, preventing, detecting cyber attacks (IDS/IPS, SIEM, SOC tool, etc.).
- Cryptographic devices for remote access, internal device administration.
- Devices/solutions that use passcode to protect access to wireless networks (Wi-Fi WPA2/WPA3…).
Specialized Hardware & Storage Components:
- Storage hard drives with SED (Self-Encrypting Drive) are widely used.
- The integrated circuit uses TPM (Trusted Platform Module) technology to authenticate the board, protect passwords.
Smart, copyright, and medical card groups:
- Smart cards and readers are for general access only, protecting personal information only.
- Solutions to protect software and digital content copyrights (DRM, anti-copying discs/videos).
- Products specially designed for use only at medical end-user terminals.
Clearly specifying the excluded product groups helps enterprises distinguish between products that use cryptographic techniques and products subject to conditional business management, thereby limiting the application of unnecessary licensing procedures. Accordingly, the determination of licensing obligations must be based on the product’s primary function, intended use and actual technical characteristics, rather than solely on whether the product incorporates cryptographic algorithms or components.
4. The “Three-Point Match” Principle for Import and Export
For export and import activities, enterprises need to simultaneously compare HS codes, descriptions of goods and cryptographic technical characteristics of products with the list in Appendix II to determine the obligation to issue licenses for export and import of civil cryptographic products.
Determination formula: Goods are only subject to the MMDS Import and Export License (term of 03 years) when and only if all 03 factors are satisfied at the same time:
- Identical HS code.
- Identical Product Description.
- Overlap Cryptographic Specification Description.
Handling the situation of HS code deviation: Priority is given to the application of the classification standards of the Customs law; According to Article 9.3, the list of products exported and imported under licenses is only applied when all three criteria mentioned above are met at the same time.
5. Licensing mechanism for “dual-use products” (cyber security and MMDS)
Decree No. 341/2026/ND-CP establishes a coordination mechanism to help resolve conflicts of authority between the Ministry of Public Security and the Main Cipher Board, ensuring uniformity of focal points but not reducing the requirements for specialized appraisal:
- Product identification: Equipment and software that simultaneously have cyber security features (management, monitoring, cyber defense), and integrate civil cryptography features such as management, monitoring, cyber defense combined with encryption, data protection or transmission lines (Article 4.5 & Article 9.4).
- Agree on the sole licensing point: Submit dossiers and receive licenses at the Ministry of Public Security for products in the cases specified in Articles 4.5 and 9.4.
- Interdisciplinary procedures – Ensuring specialized appraisal: The Ministry of Public Security is required to obtain written appraisal opinions from the Government Cipher Committee on the civil cryptography feature before granting a license.
Therefore, the new mechanism simplifies the focal point for carrying out procedures but still maintains the specialized appraisal mechanism, contributing to limiting overlapping procedures while ensuring the effectiveness of state management of civil cryptographic functions.
6. Checklist for Technology & System Integration Enterprises
Step 1. Review and classify products: Compare the entire list of equipment and software being traded with 12 groups of products excluded in Appendix I and the group of MMDS products exported and imported under the license in Appendix II issued together with Decree 341/2026/ND-CP, and check the function, purpose of use and actual technical characteristics of each product.
Step 2. Disassemble features and identify the licensing authority: Determine whether the product is a pure civil cipher or a dual-use product, thereby identifying the right authority to receive and license according to regulations.
- Government Cipher Department: Applicable if the product is purely Civil Cryptography (the main function is storage encryption, data security, or providing standard digital signature services)
- Ministry of Public Security: Applicable to dual-use products with civil cryptography and cyber security features at the same time; before licensing, the Ministry of Public Security shall consult the Government Cipher Committee in writing on the civil cryptography feature.
Step 3. Check the conditions of personnel and the system of equipment and facilities: Review the personnel structure and the system of equipment and facilities before submitting the dossier, ensuring that the conditions under Article 5.1 are met, including:
- Technical staff: Ensure that there are at least 02 people with university diplomas or higher in appropriate majors as prescribed.
- Managers and executives: At least 01 person who meets the requirements for professional qualifications; in case of graduating from a university in another discipline, they must meet additional requirements for training certificates related to information security and security as prescribed.
- Material and technical foundations: There is a system of appropriate equipment and material foundations and technical plans that meet standards and technical regulations as prescribed.
Step 4. Standardize technical documents: Prepare documents describing the product, cryptographic functions, purpose of use, specifications and documents proving business conditions, ensuring consistency between legal documents and technical documents.
Step 5. Review post-licensing obligations: Establish internal mechanisms to maintain business conditions, manage customer information, implement reporting regimes and monitor license terms throughout the operation process.
Note: The classification should be carried out on the basis of comparing functions, purposes of use, technical characteristics and product lists according to the Appendices of the Decree, thereby accurately determining the scope of management and corresponding legal obligations.
Decree No. 341/2026/ND-CP establishes a management mechanism in the direction of clearly delineating the subjects subject to licensing, specifying the scope of excluded products, delimiting the competence of dual-use products and standardizing the obligations of enterprises throughout the operation process.
For technology enterprises, the determination of legal obligations should be carried out on the basis of comparing the corresponding lists, functions, purposes of use, technical characteristics and licensing mechanisms, rather than only based on the trade name or the integration of cryptographic technology. This is the basis for enterprises to proactively classify products, identify the right competent authorities, prepare dossiers and control compliance obligations in business, import and export activities.
📩 BOOK A CONSULTATION WITH CDLAF’S LEGAL TEAM
Do not let procedural errors disrupt your business plans. Contact CDLAF today to receive a preliminary risk assessment from our team of Lawyers and E-commerce Legal Experts:
Hotline/Zalo: [+84 909 668 216]
Email: info@cdlaf.vn

Why choose CDLAF’s service?
- We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
- We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
- Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
- As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
- CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
- Strict information security procedures throughout the service performance and even after the service is completed.
You can refer for more information:
- Transferring Employees to Perform Other Works: Key Considerations for Enterprises
- Lawful Labor Discipline: Procedures and Key Notes for Enterprises
- Non-Compete Agreements In Employment Relationships: Are They Enforceable In Vietnam?
- Determining “Serious Damage” in Disciplinary Dismissal
- What Must Social Networks and Online Platforms Do to Comply with the Personal Data Protection Law 2025?
